Apparatus and method for controlling network access
Abstract
An apparatus and method for controlling network access are provided. The apparatus for controlling network access includes an authentication information acquirer configured to receive user authentication information from one or more terminals, an extensible authentication protocol (EAP) host creator configured to create one or more virtual EAP hosts for the one or more terminals, each of the one or more virtual EAP hosts performing authentication in association with an authentication system through an EAP using the received user authentication information, an authenticator configured to relay messages exchanged for the authentication between each of the one or more EAP hosts and the authentication system through the EAP and an authentication, authorization, accounting (AAA) protocol and receive an authentication result and right control information from the authentication system, and a controller configured to control network access and right for each of the one or more terminals according to the received authentication result and right control information.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus for controlling network access, comprising:
an authentication information acquirer configured to receive user authentication information from one or more terminals; an extensible authentication protocol (EAP) host creator configured to create one or more virtual EAP hosts for the one or more terminals, each of the one or more virtual EAP hosts performing authentication in association with an authentication system through an EAP using the received user authentication information; an authenticator configured to relay messages exchanged for the authentication between each of the one or more EAP hosts and the authentication system through the EAP and an authentication, authorization, accounting (AAA) protocol and receive an authentication result and right control information from the authentication system; and a controller configured to control network access and right for each of the one or more terminals according to the received authentication result and right control information.
2 . The apparatus of claim 1 , wherein the AAA protocol is one of Remote Authentication Dial-In User Service (RADIUS) protocol, DIAMETER protocol, Terminal Access Controller Access Control System (TACACS) protocol, and TACACS+ protocol.
3 . The apparatus of claim 1 , wherein the authenticator encapsulates an EAP message received from each of the one or more virtual EAP hosts into an AAA protocol message, transmits the encapsulated message to the authentication system, decapsulates an AAA protocol message for each of the one or more virtual EAP hosts, which are received from the authentication system, into an EAP message and transmits the decapsulated message to each of the one or more virtual EAP hosts.
4 . The apparatus of claim 1 , wherein the user authentication information includes a user ID and a password.
5 . The apparatus of claim 1 , further comprising an additional information collector configured to collect additional information usable in determining a network access right for each of the one or more terminals,
wherein the authenticator transmits the additional information to the authentication system.
6 . The apparatus of claim 1 , wherein the EAP host creator sets a validity period for each of the one or more virtual EAP hosts.
7 . The apparatus of claim 6 , wherein each of the one or more virtual EAP hosts performs re-authentication in association with the authentication system when the validity period has expired,
the authenticator relays messages exchanged for the re-authentication between each of the one or more virtual EAP hosts and the authentication system through the EAP and the AAA protocol and receives a re-authentication result and right control information from the authentication system, and the controller controls network access for each of the one or more terminals according to the re-authentication result and the right control information.
8 . A method of controlling network access, comprising:
receiving user authentication information from one or more terminals; creating one or more virtual extensible authentication protocol (EAP) hosts for the one or more terminals, each of the one or more virtual EAP hosts performing authentication in association with an authentication system through an EAP using the received user authentication information; relaying messages exchanged for the authentication between each of the one or more EAP hosts and the authentication system through the EAP and an authentication, authorization, accounting (AAA) protocol; receiving an authentication result and right control information from the authentication system; and controlling network access and right for each of the one or more terminals according to the received authentication result and right control information.
9 . The method of claim 8 , wherein the AAA protocol is one of Remote Authentication Dial-In User Service (RADIUS) protocol, DIAMETER protocol, Terminal Access Controller Access Control System (TACACS) protocol, and TACACS+ protocol.
10 . The method of claim 8 , wherein the relaying comprises:
encapsulating an EAP message received from each of the one or more virtual EAP hosts into an AAA protocol message; transmitting the encapsulated message to the authentication system; decapsulating an AAA protocol message for each of the one or more virtual EAP hosts, which are received from the authentication system, into an EAP message; and transmitting the decapsulated message to each of the one or more virtual EAP hosts.
11 . The method of claim 8 , wherein the user authentication information includes a user ID and a password.
12 . The method of claim 8 , further comprising collecting additional information usable in determining a network access right for each of the one or more terminals,
wherein the relaying comprises transmitting the additional information to the authentication system.
13 . The method of claim 8 , wherein the creating of the one or more virtual EAP hosts comprises setting a validity period for each of the one or more virtual EAP hosts.
14 . The method of claim 13 , further comprising:
relaying messages exchanged for re-authentication between each of the one or more virtual EAP hosts and the authentication system through the EAP and the AAA protocol, when the validity period has expired; receiving a re-authentication result and right control information from the authentication system; and controlling network access for each of the one or more terminals according to the re-authentication result and the right control information.Join the waitlist — get patent alerts
Track US2019104130A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.